Protecting Your Network with Open-Source Software
2h 47mIntermediate2024-07-18
Authors

Jungwoo Ryoo
Teaches IT, cybersecurity, and risk analysis at Penn State
Course details
Network protection is vital to organizations big and small, but it doesn't have to be an expensive proposition. In this course, Jungwoo Ryoo—a professor who teaches IT, cyber security, and risk analysis at Penn State—shows you how to protect your network with open-source tools that are completely free. Find out how to set up firewalls, investigate network traffic with a packet analyzer, detect threats and malicious activities with an intrusion-detection system, and enable network logging and monitoring. Learn about new trends in network protection and dive into demonstrations, case studies, and hands-on challenges. This course enables you to explore a low-cost route to a more secure network.
Learning objectives
Name different types of firewalls.
Explain what Netfilter is and how it’s used.
Describe what a router does.
Summarize the different types of DMZs.
Cite the hierarchy for packets, frames, and application protocol data.
Explain how to use a newly created rule file with an intrusion detection system (IDS) such as Snort.
Describe how to forward logs from Snort to logging systems like Syslog-ng and Kiwi.
Learning objectives
Name different types of firewalls.
Explain what Netfilter is and how it’s used.
Describe what a router does.
Summarize the different types of DMZs.
Cite the hierarchy for packets, frames, and application protocol data.
Explain how to use a newly created rule file with an intrusion detection system (IDS) such as Snort.
Describe how to forward logs from Snort to logging systems like Syslog-ng and Kiwi.
Skills covered
SnortNessusTenableUbuntuWiresharkCross-Platform DevelopmentMobile DevelopmentNetwork SecurityNetwork AdministrationCybersecurityNetwork and System AdministrationOpen SourceOne-Off
Concepts
0. Introduction
- 01 - Protect your network with free and open-source software
- 02 - What you should know
- 03 - Environment setup
1. Understanding Open-Source Software
- 04 - What is open-source software
- 05 - Open-source software in networking
- 06 - Open-source solutions in cybersecurity
- 07 - Open-source vs. commercial software
- 08 - Costs and savings
2. Firewalls
- 09 - What is a firewall
- 10 - Host firewalls
- 11 - Network firewalls
- 12 - Static packet filtering vs. stateful packet inspection
- 13 - Challenge - Disable UFW
- 14 - Solution - Disable UFW
3. Host as a Router
- 15 - Netfilter and iptables
- 16 - Setting up a host firewall using iptables
- 17 - Automating netfilter configuration
- 18 - Understanding hosts as routers
- 19 - Adding a network adapter
- 20 - Testing the second adapter
- 21 - Setting up IP forwarding
- 22 - Changing netfilter settings - Part 1
- 23 - Changing netfilter settings - Part 2
- 24 - Testing the router
4. Host as a Network Firewall
- 25 - Setting up hosts as network firewalls
- 26 - Setting up a web server
- 27 - Port forwarding
- 28 - Testing port forwarding
- 29 - Understanding one-legged DMZ
- 30 - Understanding true DMZ
- 31 - Understanding an application proxy firewall
- 32 - Setting up Squid
- 33 - Challenge - Fine-tuning the Squid configuration
- 34 - Solution - Fine-tuning the Squid configuration
5. Packet Analysis
- 35 - What is packet analysis
- 36 - ARP poisoning example
- 37 - Packet capturing with Wireshark
- 38 - Exploring Wireshark's advanced features
- 39 - Wireshark hands-on
- 40 - Challenge - Filtering with IP addresses and port numbers
- 41 - Solution - Filtering with IP addresses and port numbers
6. IDSs and Vulnerability Assessment
- 42 - What is an IDS
- 43 - Introducing Snort
- 44 - Snort as a packet sniffer
- 45 - Snort as an IDS - Establishing rules
- 46 - Snort as an IDS - Detecting pings
- 47 - What is a network vulnerability assessment
- 48 - Nessus
- 49 - Network scanning with Nessus
7. Logging and Monitoring
- 50 - Logging
- 51 - syslog-ng
- 52 - Log forwarding - Part 1
- 53 - Log forwarding - Part 2
- 54 - Kiwi
- 55 - SNMP
Conclusion
- 56 - Next steps